Sicherheit
Security
All tracked CVEs and security advisories — sorted by date or severity. Each entry links to the official source. The plain-text explanations are generated automatically — the source remains authoritative.
| CVE / GHSA | Item | Vertical | Severity | Date |
|---|---|---|---|---|
| CVE-2026-23631 Source Redis database has a vulnerability in its Lua scripting feature that allows authenticated attackers to execute malicious code on replica servers when certain write permissions are enabled. affects: <8.6.3 |
Redis | OS & platform | High | 06.06.2026 |
| CVE-2026-23479 Source Redis server versions 7.2.0 through 8.6.3 contain a memory handling flaw when processing blocked commands that allows authenticated attackers to execute malicious code on the server. affects: ≥7.2.0 <8.6.3 |
Redis | OS & platform | High | 06.06.2026 |
| CVE-2026-42088 Source A vulnerability in OpenC3 COSMOS allows users with script permissions to perform administrative actions through specially crafted scripts, including reading secrets from the Redis database and modifying system settings. |
Redis | OS & platform | Critical | 06.06.2026 |
| CVE-2026-42472 Source A critical vulnerability in the MixPHP Framework allows attackers to execute malicious code by injecting manipulated data into Redis sessions or cache storage, which is then unsafely deserialized. |
Redis | OS & platform | Critical | 06.06.2026 |
| CVE-2026-40872 Source A security vulnerability in the mailcow email software allows attackers to inject malicious code into admin logs that gets executed when administrators view those logs. |
Redis | OS & platform | Critical | 06.06.2026 |
| CVE-2026-35172 Source A vulnerability in Distribution software allows deleted container content to become accessible again when Redis cache and delete functionality are enabled. |
Redis | OS & platform | High | 06.06.2026 |
| CVE-2026-35052 Source A vulnerability in D-Tale (a web application for data analysis) allows attackers to execute malicious code on the server when Redis or Shelf storage layers are used. |
Redis | OS & platform | Critical | 06.06.2026 |
| CVE-2026-34977 Source A vulnerability in Aperi'Solve allows attackers to execute arbitrary code and gain full system control through unsanitized password inputs when uploading JPEG files. |
Redis | OS & platform | Critical | 06.06.2026 |
| CVE-2026-35537 Source A vulnerability in Roundcube Webmail allows unauthenticated attackers to write arbitrary files on the server by sending manipulated session data through the Redis/Memcache handler. |
Redis | OS & platform | Low | 06.06.2026 |
| CVE-2026-34163 Source FastGPT, an AI agent platform, has a vulnerability in certain endpoints that allows authenticated attackers to scan internal networks and access internal services like databases. |
Redis | OS & platform | High | 06.06.2026 |
| CVE-2026-1648 Source A WordPress plugin vulnerability allows attackers to send arbitrary web requests to internal services without authentication, potentially leading to remote server access. |
Redis | OS & platform | High | 06.06.2026 |
| CVE-2026-27794 Source A vulnerability in LangGraph's caching system allows execution of malicious code when attackers can write data to the cache storage (like Redis or SQLite) and the application later processes it. |
Redis | OS & platform | Medium | 06.06.2026 |
| CVE-2026-2970 Source A vulnerability in datapizza-ai software allows attackers on the local network to inject and execute malicious data through the Redis cache function. |
Redis | OS & platform | Medium | 06.06.2026 |
| CVE-2026-27574 Source OneUptime monitoring software allows users to execute JavaScript code that can easily escape its security sandbox, enabling complete system access and exposure of all stored passwords and credentials. |
Redis | OS & platform | Critical | 06.06.2026 |
| CVE-2026-27022 Source A vulnerability in the Redis checkpoint library for LangGraph allows attackers to manipulate database queries through specially crafted filter inputs and potentially access unauthorized data. |
Redis | OS & platform | Medium | 06.06.2026 |
| CVE-2026-26991 Source LibreNMS, a network monitoring tool, has an input validation weakness in device group names that allows administrators to inject malicious scripts that get displayed to other users. |
Redis | OS & platform | Medium | 06.06.2026 |
| CVE-2026-43917 Source A security flaw in Dokploy, a self-hostable platform software, allows authenticated users to access resources belonging to other organizations due to incomplete access control implementation. |
MariaDB | OS & platform | Medium | 06.06.2026 |
| CVE-2026-46446 Source A SQL injection vulnerability in SOGo (not MariaDB itself) allows attackers to inject malicious database commands when cleartext passwords are stored using PostgreSQL or MariaDB databases. |
MariaDB | OS & platform | High | 06.06.2026 |
| CVE-2026-35549 Source A flaw in MariaDB database servers allows attackers to crash the server by sending large data packets when the caching_sha2_password plugin is enabled. affects: <11.4.10; ≥11.5.0 <11.8.6; ≥12.0.0 <12.2.2 |
MariaDB | OS & platform | Medium | 06.06.2026 |
| CVE-2026-32710 Source A vulnerability in MariaDB's JSON_SCHEMA_VALID() function allows authenticated users to crash the database server and potentially execute malicious code under specific circumstances that are difficult to achieve outside laboratory conditions. affects: ≥11.4.1 <11.4.10; ≥11.8.1 <11.8.6; =12.1.2 |
MariaDB | OS & platform | High | 06.06.2026 |
| CVE-2026-22730 Source A security flaw in Spring AI's MariaDB component allows attackers to inject and execute malicious SQL commands, bypassing access controls and potentially compromising database data. |
MariaDB | OS & platform | High | 06.06.2026 |
| CVE-2026-3494 Source In MariaDB database servers up to version 11.8.5, SQL commands starting with certain comment characters are not logged when the audit plugin is enabled. This can bypass security monitoring. affects: ≤10.6.24; ≥10.7.0 ≤10.11.15; ≥11.0.0 ≤11.4.9; ≥11.5.0 ≤11.8.5 |
MariaDB | OS & platform | Medium | 06.06.2026 |
| CVE-2026-10107 Source MoviePilot v2 contains a vulnerability that allows authenticated attackers to target arbitrary internal network services and steal data by bypassing insufficient URL filtering in the image proxy endpoint. |
Jellyfin | Self-hosted apps | High | 06.06.2026 |
| CVE-2026-41167 Source A security vulnerability in Jellystat (a statistics app for Jellyfin) allows authenticated users to inject malicious SQL code, enabling them to read sensitive data or even execute arbitrary commands on the server. |
Jellyfin | Self-hosted apps | Critical | 06.06.2026 |
| CVE-2026-35034 Source A vulnerability in Jellyfin versions before 10.11.7 allows authenticated users to create groups with extremely long names, blocking the SyncPlay service for others and potentially causing server crashes due to excessive memory usage. affects: <10.11.7 |
Jellyfin | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2026-35033 Source Jellyfin media server before version 10.11.7 has a critical security flaw that allows attackers to read arbitrary files from the server without authentication by injecting malicious parameters into video streaming requests. affects: <10.11.7 |
Jellyfin | Self-hosted apps | Critical | 06.06.2026 |
| CVE-2026-35032 Source Jellyfin media server before version 10.11.7 has a security flaw that allows logged-in users to read local files and gain admin privileges by exploiting manipulated Live TV settings. affects: <10.11.7 |
Jellyfin | Self-hosted apps | High | 06.06.2026 |
| CVE-2026-35031 Source A critical security vulnerability in Jellyfin Media Server allows administrators or users with subtitle upload permissions to write arbitrary files and ultimately gain complete system control as root user. affects: <10.11.7 |
Jellyfin | Self-hosted apps | Critical | 06.06.2026 |
| CVE-2026-32891 Source A security flaw in the Anchorr Discord bot allows attackers to inject malicious code into admin browsers, gaining complete system access and control over all connected services including Jellyfin media servers. |
Jellyfin | Self-hosted apps | Critical | 06.06.2026 |
| CVE-2026-32890 Source A security flaw in the Anchorr Discord bot allows any Discord user to execute malicious code in the administrator's browser and steal all stored passwords and API keys. |
Jellyfin | Self-hosted apps | Critical | 06.06.2026 |
| CVE-2026-31852 Source A vulnerability in the GitHub Actions workflows of the Jellyfin iOS app allows attackers to execute arbitrary code and gain full repository control, potentially leading to secret theft and supply chain attacks. |
Jellyfin | Self-hosted apps | Critical | 06.06.2026 |
| CVE-2026-27793 Source A vulnerability in Seerr, a media manager for Jellyfin and other streaming servers, exposes sensitive user data including API keys for Pushover and Telegram to any authenticated user, regardless of their permission level. |
Jellyfin | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2026-27792 Source A vulnerability in Seerr (a media manager for Jellyfin) allows authenticated users to access and modify other users' data because certain API routes lack proper authorization checks. |
Jellyfin | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2026-27707 Source A vulnerability in Seerr software allows attackers to register accounts without valid credentials by using their own Jellyfin server, even when Seerr is configured for Plex instead. |
Jellyfin | Self-hosted apps | High | 06.06.2026 |
| CVE-2026-33380 Source A vulnerability in Grafana allows authenticated users to read arbitrary files from the server when the SQL Expressions feature is enabled. affects: ≥11.6.0 <11.6.14; ≥12.2.0 <12.2.8; ≥12.3.0 <12.3.6; ≥12.4.0 <12.4.3; ≥13.0.0 <13.0.1 |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2026-28383 Source A vulnerability in Grafana allows authenticated users to consume unlimited memory through special requests to plugin endpoints, potentially crashing the server and causing service disruption. affects: ≥8.5.0 <11.6.14; ≥12.2.0 <12.2.8; ≥12.3.0 <12.3.6; ≥12.4.0 <12.4.3; =11.6.14; =12.2.8; =12.3.6; =12.4.3 |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2026-28379 Source A vulnerability in Grafana Live allows authenticated users with Viewer permissions to crash the server through concurrent requests, causing complete service outage until restart. affects: ≥8.5.0 <11.6.14; ≥12.2.0 <12.2.8; ≥12.3.0 <12.3.6; ≥12.4.0 <12.4.3; =11.6.14; =12.2.8; =12.3.6; =12.4.3 |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2026-28376 Source A vulnerability in Grafana's Live push feature allows authenticated users to cause unlimited memory consumption by sending large amounts of data, potentially leading to system crashes. affects: ≥8.0.0 <11.6.14; ≥12.0.0 <12.2.8; ≥12.3.0 <12.3.6; ≥12.4.0 <12.4.3; =11.6.14; =12.2.8; =12.3.6; =12.4.3 |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2026-21727 Source A vulnerability in Grafana's Correlations feature allows users with datasource management privileges to view and permanently delete legacy correlation data belonging to other organizations, bypassing tenant isolation. affects: <11.6.11; ≥12.0.0 <12.0.9; ≥12.1.0 <12.1.6; ≥12.2.0 <12.2.4; ≥12.3.0 <12.3.3 |
Grafana | OS & platform | Low | 06.06.2026 |
| CVE-2025-12141 Source In Grafana's notification system, users with edit permissions can modify endpoint URLs of other users' contact points and capture confidential credentials like Slack tokens through the test function, enabling unauthorized access to external services. affects: ≥8.0.0 ≤12.3.0 |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2026-28375 Source A vulnerability in Grafana's test data source can be exploited to cause memory issues that crash the application. affects: <8.1.0; ≥11.6.14 <12.0.0; ≥12.1.10 <12.2.0; ≥12.2.8 <12.3.0; ≥12.3.6 <12.4.0 |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2026-27879 Source A vulnerability in Grafana allows attackers to cause system crashes by overwhelming memory through specially crafted resample queries, leading to denial of service. affects: <8.0.0; ≥11.6.14 <12.0.0; ≥12.1.10 <12.2.0; ≥12.2.8 <12.3.0; ≥12.3.6 <12.4.0 |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2026-27876 Source A vulnerability in Grafana allows attackers to execute arbitrary code on the server through a combination of SQL expressions and Enterprise plugins. Only instances with the sqlExpressions feature enabled in specific versions between 11.6.0 and 12.4.1 are affected. affects: <11.6.0; ≥11.6.14 <12.0.0; ≥12.1.10 <12.2.0; ≥12.2.8 <12.3.0; ≥12.3.6 <12.4.0 |
Grafana | OS & platform | Critical | 06.06.2026 |
| CVE-2026-28377 Source A vulnerability in Grafana Tempo exposes the S3 encryption key in plain text through a status endpoint, allowing unauthorized individuals to access the key used for encrypted trace data. |
Grafana | OS & platform | High | 06.06.2026 |
| CVE-2026-33375 Source A vulnerability in Grafana's MSSQL plugin allows low-privileged users to bypass security restrictions and crash the server by causing excessive memory consumption. affects: ≥11.6.0 <11.6.14; ≥12.1.0 <12.1.10; ≥12.2.0 <12.2.8; ≥12.3.0 <12.3.6; ≥12.4.0 <12.4.2 |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2026-21724 Source A vulnerability in Grafana allows users with Editor role to modify protected webhook URLs despite lacking the required permissions for such changes. affects: ≥11.6.9 <11.6.14; ≥12.1.5 <12.1.10; ≥12.2.2 <12.2.8; ≥12.3.1 <12.3.6 |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2026-32117 Source A security vulnerability in the Grafana Cubism panel plugin allows attackers with editor privileges to inject malicious JavaScript code that executes when other users interact with the panel. affects: ≤0.1.2 |
Grafana | OS & platform | High | 06.06.2026 |
| CVE-2026-21725 Source A vulnerability in Grafana allows attackers to delete data sources without permission if they were previously deleted and then recreated. This requires very specific conditions to be met and only works within a 30-second window. affects: ≥11.0.0 <12.4.1 |
Grafana | OS & platform | Low | 06.06.2026 |
| CVE-2025-41117 Source A vulnerability in Grafana's Explore Traces view allows attackers to inject malicious JavaScript code through stack traces, which then executes in the browser. Only data sources using Jaeger HTTP API are affected. affects: ≥12.2.0 <12.2.4; ≥12.3.0 <12.3.2; =12.2.4; =12.3.2 |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2026-27590 Source A vulnerability in Caddy's FastCGI path processing can cause incorrect PHP files to be executed due to Unicode character handling, potentially leading to unintended code execution when file contents are controllable. |
Caddy | OS & platform | High | 06.06.2026 |